ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-37333
+2 in the same advisory: …37330 …37331
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.

Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • bookingcore booking core
CVE-2020-25445
+2 in the same advisory: …27379 …25444
The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection.

The “Subscribe” feature in Ultimate Booking System Booking Core 1.7.0 is vulnerable to CSV formula injection. The input containing the excel formula is not being sanitized by the application. As a result when admin in backend download and open the csv, content of the cells are executed.

NVD description · AI analysis pending
7.8
group max
<1%
  • bookingcore booking core